CVE-2005-2149
published 2005-07-06CVE-2005-2149: config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and…
PriorityP434critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.31%
81.5th percentile
config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cacti | cacti | >= 0 < 0.8.6f-1 | 0.8.6f-1 |
| cacti | cacti | >= 0 < 0.8.6f-1 | 0.8.6f-1 |
| cacti | cacti | >= 0 < 0.8.6f-1 | 0.8.6f-1 |
| cacti | cacti | >= 0 < 0.8.6f-1 | 0.8.6f-1 |
| debian | cacti | < cacti 0.8.6f-1 (bookworm) | cacti 0.8.6f-1 (bookworm) |
| the_cacti_group | cacti | — | — |
| the_cacti_group | cacti | — | — |
| the_cacti_group | cacti | — | — |
| the_cacti_group | cacti | — | — |
| the_cacti_group | cacti | — | — |
| the_cacti_group | cacti | — | — |
| the_cacti_group | cacti | — | — |
| the_cacti_group | cacti | — | — |
| the_cacti_group | cacti | — | — |
| the_cacti_group | cacti | — | — |
| the_cacti_group | cacti | — | — |
| the_cacti_group | cacti | — | — |
| the_cacti_group | cacti | — | — |
| the_cacti_group | cacti | — | — |
| the_cacti_group | cacti | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2005-2149: cacti - config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_htt...
vendor_debian·2005·CVSS 10.0
CVE-2005-2149 [CRITICAL] CVE-2005-2149: cacti - config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_htt...
config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.
Scope: local
bookworm: resolved (fixed in 0.8.6f-1)
bullseye: resolved (fixed in 0.8.6f-1)
forky: resolved (fixed in 0.8.6f-1)
sid: resolved (fixed in 0.8.6f-1)
trixie: resolved (fixed in 0.8.6f-1)
GHSA
GHSA-r2fr-8m3m-rwqg: config
ghsa_unreviewed·2022-05-01
CVE-2005-2149 [HIGH] GHSA-r2fr-8m3m-rwqg: config
config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.
OSV
CVE-2005-2149: config
osv·2005-07-06·CVSS 10.0
CVE-2005-2149 [CRITICAL] CVE-2005-2149: config
config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://securitytracker.com/id?1014361http://sourceforge.net/mailarchive/forum.php?forum_id=10360&max_rows=25&style=flat&viewmonth=200507&viewday=1http://www.cacti.net/downloads/patches/0.8.6e/cacti-0.8.6f_security.patchhttp://www.debian.org/security/2005/dsa-764http://www.hardened-php.net/advisory-052005.phphttp://www.securityfocus.com/archive/1/404040http://www.securityfocus.com/bid/14130http://www.vupen.com/english/advisories/2005/0951http://securitytracker.com/id?1014361http://sourceforge.net/mailarchive/forum.php?forum_id=10360&max_rows=25&style=flat&viewmonth=200507&viewday=1http://www.cacti.net/downloads/patches/0.8.6e/cacti-0.8.6f_security.patchhttp://www.debian.org/security/2005/dsa-764http://www.hardened-php.net/advisory-052005.phphttp://www.securityfocus.com/archive/1/404040http://www.securityfocus.com/bid/14130http://www.vupen.com/english/advisories/2005/0951
2005-07-06
Published